9.8

CVE-2023-39439

SAP Commerce accepts empty passphrases.

SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphrase.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAPCommerce Cloud Version2211
SAPCommerce Hycom Version2105
SAPCommerce Hycom Version2205
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.594
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cna@sap.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-258 Empty Password in Configuration File

Using an empty string as a password is insecure.